Threat Database Trojans Trojan.MSIL.Krypt.EEBU

Trojan.MSIL.Krypt.EEBU

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 22,558
Threat Level: 80 % (High)
Infected Computers: 457
First Seen: April 1, 2022
Last Seen: July 18, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.EEBU on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it's essential to understand its nature and how to remove it effectively.

What Is Trojan.MSIL.Krypt.EEBU?

Trojan.MSIL.Krypt.EEBU is a type of Trojan horse malware that can sneak into your system without your knowledge or consent. The name itself suggests it's a Trojan-type threat, but without more specific information, it's difficult to determine its exact origins or the extent of its capabilities. Generally, Trojans are known for their ability to disguise themselves as legitimate programs, making them challenging to detect and remove.

How Trojan.MSIL.Krypt.EEBU Operates

Once installed on your system, Trojan.MSIL.Krypt.EEBU can operate in various ways, depending on its design and purpose. It may attempt to connect to remote servers to download additional malware, steal sensitive information such as login credentials or financial data, or provide unauthorized access to your system. The malware can also modify system settings, disable security software, or create backdoors for future attacks. Understanding how it operates is crucial for developing an effective removal strategy.

Symptoms of Infection

The symptoms of a Trojan.MSIL.Krypt.EEBU infection can vary, but common indicators include slow system performance, frequent crashes, or unusual behavior from your computer. You might also notice unfamiliar programs or icons on your desktop, unexpected changes to your browser settings, or pop-ups and advertisements appearing on your screen. In some cases, the malware may run silently in the background, making it difficult to detect without proper scanning tools.

How to Remove Trojan.MSIL.Krypt.EEBU

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to gain better control over your system.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove the malware and any associated files or registry entries.
  3. Uninstall any suspicious programs that you don't recognize or that were installed around the time the malware was detected. Be cautious and only remove programs you are certain are not necessary for your system's operation.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes made by the malware.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that the malware has been completely removed and that your system is clean.

Conclusion

Removing Trojan.MSIL.Krypt.EEBU requires a combination of technical knowledge and the right tools. By following the steps outlined above and maintaining good security practices, such as keeping your operating system and software up to date, using strong passwords, and being cautious with email attachments and downloads, you can significantly reduce the risk of future infections. Remember, prevention and vigilance are key to protecting your digital assets and ensuring the security and integrity of your computer system.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.EEBU
Signature status: No Signature

Known Samples

MD5: b85abd5b9cf1030f48277e3f1796d9ec
SHA1: a585984d71fe9dbee1c74aca9d2c646f7cccf1c4
SHA256: 4C4E1CD0E2349ECDDF3EC7E8CAF7115FD5A8708497424A48C18CF9170318CB6F
File Size: 892.42 KB, 892416 bytes
MD5: bd8c2bf03d242d93fa09557224d5dd55
SHA1: f31caebe900f8ff121c21372be2857fcf8735a60
SHA256: 0BA1E912EAB9ACF4784B1BF9703E078329E9BB081FB39817A83088E39BD072FB
File Size: 1.40 MB, 1395712 bytes
MD5: 71cb68ab4434d8afb9578957a66111cf
SHA1: 87774097bc1d592274222bee410e4dcd70fc3279
SHA256: FFFCD2E9E26B5CDE88DA4AA1AFA21AD793C16B3FC6DE9F54C559E4485BEAB2A0
File Size: 1.01 MB, 1014272 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 16.10.0.0
  • 4.5.3.0
  • 2.4.9288.31366
Comments
  • Integrated system level solution for programming, configuring and tuning software for DSP audio processors, A2B transceivers and Audio Algorithms
  • Provides a ProppFrexx Media Library Server
Company Name
  • Analog Devices, Inc.
  • C Tech Development Corporation
  • radio42
File Description
  • EnterVolHost
  • ProppFrexx MediaLibraryServer
  • SigmaStudio+
File Version
  • 16.10.0.0
  • 4.5.3.0
  • 2.4.9288.31366
Internal Name
  • EnterVolHost.exe
  • ProppFrexx MediaLibraryServer.exe
  • SigmaStudio.exe
Legal Copyright
  • Copyright © 2009-2026 radio42, Bernd Niedergesaess, Germany.
  • Copyright © 2013 ctech.com
  • Copyright© 2024
Original Filename
  • EnterVolHost.exe
  • ProppFrexx MediaLibraryServer.exe
  • SigmaStudio.exe
Product Name
  • EnterVol for ArcGIS
  • ProppFrexx MediaLibraryServer
  • SigmaStudio+
Product Version
  • 16.10.0.0
  • 4.5.3.0
  • 2.4.9288.31366

File Traits

  • .NET
  • .sdata
  • Reactor
  • RijndaelManaged
  • x64
  • x86

Block Information

Total Blocks: 174
Potentially Malicious Blocks: 0
Whitelisted Blocks: 59
Unknown Blocks: 115

Visual Map

? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? 0 0 ? 0 0 ? ? ? ? ? ? ? ? 0 0 ? 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.ACLE
  • MSIL.HackAgent.RE
  • MSIL.Krypt.MBAO
  • MSIL.Krypt.MBAXB
  • MSIL.Spy.Agent.DN
Show More
  • MSIL.Spy.QJ

Registry Modifications

Key::Value Data API Name
HKCU\software\radio42\proppfrexx medialibraryserver::lasterror Could not load file or assembly 'DevExpress.Data.v25.2, Version=25.2.6.0, Culture=neutral, PublicKeyToken=b88d1754d700e49a' or o RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
Show More
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation

Related Posts

Trending

Most Viewed

Loading...